JustAppSec

Application security, made easier.

Free tools, practical guides, hands-on training, and CVE intelligence for people building resilient software.

All news →

Latest news

All news →

Research

View all →

Deep dives on how attacks work, real-world impact, and prevention guidance. Got a topic request? Let us know.

Threat Model Tool

Open tool →

A free, local-first threat modelling tool. Map your system, identify threats, assign risk ratings, and track mitigations - all in the browser with no data leaving your machine. Export to PDF, generate AI prompts, and map threats to Cyber Essentials controls.

Local-firstRisk matrixCyber Essentials mappingAI prompt generation

AppSec Scorecard

Take the assessment →

A lightweight security fundamentals assessment. 10 yes/no questions you can answer in 5 minutes to benchmark your AppSec baseline, identify quick wins, and track improvements over time. Export a PDF report to share with leadership.

Practical, task-focused playbooks and checklists you can use right away.

A hands-on, lifecycle-first journey through application security. Six pathways follow the software lifecycle - from building a security mindset to breaking your own apps before someone else does.

We've modernised appsec training around the way software actually gets built:

  1. 1
    ThinkBuild a security mindset: threats, boundaries, and intent.5 lessons
  2. 2
    CodeWrite secure code: injection, auth, validation, and defence in depth.8 lessons
  3. 3
    BuildDesign systems that defend themselves: frameworks, APIs, and architecture.6 lessons
  4. 4
    ShipSecure the pipeline: CI/CD, dependencies, containers, and provenance.6 lessons
  5. 5
    RunDetect and respond: logging, monitoring, incidents, and compliance.6 lessons
  6. 6
    BreakFind what others miss: testing, review, and offensive techniques.6 lessons

CVE Database

Search CVEs →

Searchable CVE records with CVSS scores, severity filters, and affected-product lookups. Filter by critical/high severity, recently published, or recently updated.

Need help?Get in touch.